MORE POSTS
September 17, 2012 8:17 PM
How to Launch a 65Gbps DDoS, and How to Stop One
Yesterday I posted a post mortem on an outage we had Saturday. The outage was caused when we applied an overly aggressive rate limit to traffic on our network while battling a determined DDoS attacker. ...
August 28, 2012 5:44 PM
Turning "I'm Under Attack" into "I'm Doing Some Good"
CloudFlare's I'm Under Attack mode allows our customers to, at the click of a button, tell us that they are experiencing an attack and enable automatic protection. It works by slowing down visits to the web site that's under attack and performing extra work to identify malicious ...
August 16, 2012 8:58 AM
Saturday Night Fever: Layer 7 attacks against CloudFlare sites
Recently, I've taken a look at DDoS attacks against CloudFlare sites at the IP level and the source of those attacks. The worst time for those DDoS attacks is the Wednesday Witching Hour and because of source IP address forgery most of the attacks seem to come from Mars. ...
August 06, 2012 2:06 PM
Mars Attacks!
Following on from my recent post about when attacks hit CloudFlare, here's a follow up looking at where they come from. Or at least where they say they come from. Looking at attack statistics for the month of July 2012 the largest source of attacks is Mars....
August 03, 2012 3:06 PM
The Wednesday Witching Hour: CloudFlare DoS Statistics
Data from inside CloudFlare's network shows that over 40% of the time there's a denial of service attack happening and directed at us. And that's just up to network layer 4 (i.e. it doesn't include more sophisticated attacks targeting applications themselves at layer 7)....
June 04, 2012 10:02 PM
The Four Critical Security Flaws that Resulted in Last Friday's Hack
A core value CloudFlare is that security information should be shared between organizations to make the entire Internet safer. That is how CloudFlare's systems work: if one site is attacked, data about that attack is immediately shared with the rest of the network so other sites ...
June 01, 2012 10:22 PM
Post Mortem: Today's Attack; Apparent Google Apps/Gmail Vulnerability; and How to Protect Yourself
This morning a hacker was able to access a customer's account on CloudFlare and change that customer's DNS records. The attack was the result of a compromise of Google's account security procedures....
December 21, 2011 11:04 PM
2011: The Year of the DDoS
As the year comes to a close, we've been assembling trend data for 2011. One of the most interesting has been the rise of denial of service (DDoS) attacks. Controlling for CloudFlare's growth, we've seen a 700% increase in DDoS attacks over the course of the year....
December 15, 2011 12:28 AM
Do Hackers Take the Holidays Off?
I was talking last week with Shawn Graham, a reporter at Fast Company, and he asked a simple but interesting question: do hackers take the holidays off?...
November 16, 2011 6:59 PM
SOPA Could Create New Denial of Service Attack, Powered by Law not Botnets
The United States House of Representatives is considering the Stop Online Piracy Act, known as SOPA. Companies including Google, Zynga, Facebook, Yahoo, AOL, and Mozilla, along with organizations like the Electronic Frontier Foundation (EFF) have been sharply critical of the law....
August 24, 2011 11:54 PM
Apache Killer Terminated: Zero Day Exploit, Zero Day Fix
Early this morning word spread that there was a zero day exploit dubbed the "Apache Killer." The exploit uses malformed Apache byte-range headers to crash the web server. The exploit is effective against the latest versions of Apache as well as versions back to v1.3. ...
July 20, 2011 6:12 PM
Breaking the Cycle of Malware
Google did something terrific yesterday. They began notifying users with a certain kind of malware running on their PCs that they had a problem and linked them to tools to help clean it up. While it is currently limited, we think this is an important step by Google....
May 18, 2011 5:16 PM
That's Freaking Awesome: CloudFlare Automatically Learns How to Stop New Attacks
We always talk about how CloudFlare gets smarter, and we do that in a variety of ways. One of the ways is that we look at changes in traffic to a site. If there is a big change, then our system automatically starts to investigate whether it is legitimate traffic or an attack. ...